Military Contractors Face False Claims Act Exposure After CMMC Phase 2 Suspension
Originally Published: Nov. 24, 2025
Last Updated: Aug. 14, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
This page was updated on Aug. 14, 2026 to reflect the suspension of Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements, a new defense contractor settlement under the False Claims Act (FCA), and current Department of Justice (DOJ) enforcement statistics.
A Massachusetts defense contractor agreed to pay $4.6 million to settle allegations it violated the False Claims Act by failing to meet cybersecurity requirements tied to Department of Defense (DoD) contracts. The MORSECORP case (PDF) represents far more than an isolated compliance failure. It signals an enforcement trend that continues to expand, and a separate settlement announced in June 2026 shows the government isn't slowing down.
The DOJ increasingly treats cybersecurity compliance failures as potential fraud against the government when contractors knowingly misrepresent their security posture while continuing to receive federal funds. For military suppliers, cybersecurity is no longer simply an information technology (IT) issue or operational concern. It's a contractual, legal, financial, and executive governance issue, and a July 2026 policy shift at the Pentagon changes how contractors should think about the third-party assessment side of that risk without changing the underlying legal exposure.
What Happened at MORSECORP
Between January 2018 and February 2023, MORSECORP submitted payment claims to the Department of Defense while allegedly failing to implement required cybersecurity controls under Defense Federal Acquisition Regulation Supplement (DFARS) and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 requirements.
The most significant issue involved the company's self-reported NIST SP 800-171 score. MORSECORP reportedly submitted a score of 104 into the Supplier Performance Risk System (SPRS) in January 2021. A third-party cybersecurity consultant later determined the company's actual score was negative 142, indicating severe control deficiencies.
According to the settlement allegations, roughly 78% of required controls were either partially implemented or entirely missing. Despite learning about these deficiencies, MORSECORP allegedly delayed updating its SPRS score for nearly a year.
The company also allegedly:
- Used third-party email services that didn't meet Federal Risk and Authorization Management Program (FedRAMP) Moderate requirements
- Operated without adequate system security plans (SSPs)
- Failed to properly implement required NIST SP 800-171 controls
- Continued accepting federal contract payments while deficiencies remained unresolved
The result was a $4.6 million settlement, including substantial restitution and a significant whistleblower payout.
New Settlement Shows Pattern Repeating
On June 18, 2026, DOJ announced a $507,144 settlement with LOGZONE Inc., a Huntsville, Ala., defense logistics and training contractor, resolving allegations that the company knowingly failed to meet cybersecurity requirements in its contracts with the Department of the Navy. The settlement followed a coordinated review involving the Navy, the Army, and the Defense Contract Management Agency, and it reached DOJ through the same self-reported SPRS scoring process that undermined MORSECORP.
The LOGZONE case matters for a reason beyond its dollar amount. It's the clearest sign yet that DOJ is treating a contractor's own Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) score, not just a whistleblower tip, as a direct pathway into an FCA investigation. A government-led validation that contradicts a contractor's self-reported score can become the factual basis for a fraud case on its own.
Cybersecurity Failures Becoming False Claims Act Cases
The MORSECORP and LOGZONE matters are part of a broader DOJ strategy under the Civil Cyber-Fraud Initiative, launched in 2021. The initiative targets companies that knowingly misrepresent cybersecurity practices, submit inaccurate compliance attestations, fail to meet contractual cybersecurity obligations, conceal known security deficiencies, or continue billing the government while materially noncompliant.
Speaking at the American Conference Institute's Advanced Forum on False Claims and Qui Tam Enforcement on Jan. 28, 2026, Deputy Assistant Attorney General Brenna Jenny said DOJ recovered $52 million across nine cyber-related FCA settlements in the fiscal year that ended in September 2025, describing it as a "significant upward trajectory," according to a summary of her remarks published by Akin Gump. Jenny added that cyber-fraud cases are "not about data breaches" but rest on knowing misrepresentations, and that nine of DOJ's 15 cyber-related settlements at that point involved DoD cybersecurity requirements specifically.
Several other notable cybersecurity-related FCA enforcement actions have emerged in recent years:
- Aerojet Rocketdyne faced allegations involving false cybersecurity certifications tied to military and National Aeronautics and Space Administration (NASA) contracts.
- Verizon Business Network Services agreed to resolve allegations tied to failures involving federal network security requirements.
- Comprehensive Health Services settled claims involving inadequate protection of sensitive military personnel and medical data.
- Cisco Systems previously resolved allegations involving the sale of products with known security vulnerabilities to government customers.
These cases show a shift in federal enforcement priorities that predates and outlasts any single administration's policy on the certification process itself. Cybersecurity deficiencies aren't viewed solely as technical problems. Inaccurate cybersecurity representations can create significant fraud exposure under the False Claims Act, regardless of which office reviews the score.
CMMC Phase 2 Suspension Doesn't Reduce False Claims Act Risk
On July 13, 2026, the Department of War suspended the rollout of CMMC Phase 2, the requirement that would have made independent third-party certification through a Certified Third-Party Assessor Organization (C3PAO) a condition of contract award starting Nov. 10, 2026. Department of War Chief Information Officer Kirsten Davies established a CMMC Reform Task Force to review the entire program and deliver recommendations by mid-September 2026, informed in part by a public request for information with comments due Aug. 14, 2026, according to the Small Business Administration's Office of Advocacy.
Under Secretary of War for Acquisition and Sustainment Michael Duffey framed the pause as a way to reduce compliance costs for smaller contractors rather than a relaxation of security expectations, telling reporters the department is removing "the bureaucracy of the third-party assessment," not the underlying standard, according to reporting from DefenseScoop. Phases 3 and 4 of the CMMC rollout, along with all future implementation milestones, are frozen along with Phase 2 until the department issues further guidance.
Contractors should read this pause narrowly. What changed is the verification mechanism, meaning who checks your cybersecurity score before award. What didn't change is the underlying legal obligation. DFARS clause 252.204-7012 still requires implementation of NIST SP 800-171, CMMC Phase 1 self-assessment and annual affirmation requirements remain active, and SPRS score submissions still carry False Claims Act exposure if they're discovered to be inaccurate.
The LOGZONE settlement closed less than a month before the Phase 2 suspension, and it was built entirely on a self-assessment score, not a C3PAO audit. Removing the third-party check doesn't remove the risk that a self-reported score becomes the basis for a fraud claim. If anything, it puts more weight on a contractor's own attestation, since no independent assessor will catch an inflated score before it reaches SPRS.
How Good Companies Get in Trouble
Most False Claims Act cybersecurity cases start with shortcuts, assumptions, and pressure to keep contracts moving.
A contractor may inherit outdated systems after an acquisition and delay remediation because production deadlines take priority. Another company may rely on self-assessment scores that were never independently validated. Leadership teams sometimes assume partial implementation is close enough and continue certifying compliance while major gaps remain unresolved.
In other cases, suppliers centralize operations across multiple acquired companies without realizing weak onboarding, identity management, or vendor oversight processes are now spreading risk across the entire business. In some cases, the acquiring company forces the acquired military supplier to reduce its security practices.
What begins as operational convenience can quickly evolve into contractual risk if a contractor continues accepting federal funds while cybersecurity representations no longer match reality.
Many companies don't realize they have a serious problem until:
- A whistleblower reports internal concerns
- An outside consultant performs a real assessment
- A prime contractor requests supporting evidence
- A cyber incident exposes long-ignored weaknesses
- A government-led DIBCAC review contradicts a self-reported score
By that point, legal exposure, reputational damage, and contract risk may already be growing.
Cybersecurity as Board-Level Business Risk
Many defense contractors still approach cybersecurity primarily as an information technology issue or a compliance checkbox. DOJ enforcement actions increasingly show cybersecurity governance failures can create enterprise-level business risk involving False Claims Act liability, whistleblower lawsuits, suspension and debarment risk, loss of federal contracts, mergers and acquisitions due diligence failures, reputational damage, and operational disruption following breaches or investigations.
The biggest cybersecurity risk for many defense contractors is inaccurate compliance representations, not the absence of a security program.
This risk becomes especially significant for companies rapidly acquiring businesses, consolidating operations, or integrating multiple business units under centralized governance structures.
Weak identity management, inconsistent onboarding processes, inherited technical debt, poor vendor oversight, and inaccurate compliance tracking can quickly create systemic cybersecurity risk across an entire enterprise.
Acquisitions Can Multiply Cybersecurity Risk
Rapid acquisition strategies create unique cybersecurity challenges throughout the defense industrial base.
When companies acquire multiple contractors and quickly centralize operations, weak governance decisions can spread across every business unit. Identity management shortcuts, inconsistent personnel screening, inherited technical debt, and incomplete documentation often become enterprise-wide problems.
Many leadership teams underestimate how difficult it is to integrate multiple environments handling controlled unclassified information (CUI) while maintaining accurate NIST SP 800-171 compliance across all systems.
As mergers and acquisitions continue throughout the defense industrial base (DIB), cybersecurity due diligence remains important during both the acquisition and integration phases, regardless of where CMMC's certification requirement lands after the reform review.
Understanding NIST SP 800-171 and DFARS Obligations
NIST SP 800-171 establishes required security controls for protecting CUI within non-federal systems and companies.
Defense contractors handling CUI are expected to implement 110 security requirements covering access control, incident response, audit logging, personnel security, configuration management, media protection, risk assessment, and system and communications protection.
DFARS clauses and associated SPRS reporting obligations require contractors to accurately assess and report implementation status. These self-assessments aren't administrative paperwork. They're representations tied directly to federal contracting eligibility and payment, and they remain fully enforceable during the Phase 2 pause.
Difference Between Deficiencies and Deception
Most defense contractors are still maturing their cybersecurity programs. Many companies continue working through implementation challenges tied to NIST SP 800-171, DFARS requirements, and CMMC.
Federal enforcement actions generally focus less on the existence of deficiencies themselves and more on knowingly inaccurate compliance representations, failure to disclose major deficiencies, fabricated documentation, concealment after internal discovery of serious gaps, and continued misrepresentation after receiving professional assessments.
A supplier may honestly believe it's compliant because a spreadsheet says controls are in place. Then an outside assessor discovers multifactor authentication (MFA) wasn't fully enforced, logging wasn't retained properly, vendors weren't reviewed, and system security plans are outdated. What leadership viewed as an IT cleanup project can suddenly become a contractual and legal problem.
Companies that conduct honest assessments, maintain accurate documentation, develop remediation plans, and report deficiencies transparently are in a much stronger position than contractors attempting to hide problems or inflate compliance status.
Whistleblower Risk Remains High
The False Claims Act includes provisions allowing private individuals to file lawsuits on behalf of the federal government.
Employees, consultants, IT personnel, subcontractors, former staff, and industry insiders who become aware of significant cybersecurity misrepresentations may receive a percentage of recovered funds if the government intervenes successfully.
In the MORSECORP matter, the whistleblower reportedly received $851,000 as part of the settlement.
Companies that ignore internal warnings, suppress security concerns, or pressure employees to minimize deficiencies significantly increase both legal and reputational risk, and the removal of a third-party assessment step during the CMMC pause doesn't remove that internal-reporting pathway.
Where CMMC Stands Today
CMMC is currently active in two parts. The program rule, 32 CFR Part 170, established the CMMC program itself and took effect Dec. 16, 2024. The acquisition rule, implemented through DFARS, put CMMC into DoD contracts and took effect Nov. 10, 2025. Both remain on the books.
Phase 1, which covers Level 1 and Level 2 self-assessments submitted to SPRS, took effect Nov. 10, 2025, and continues today. Phase 2, which would have required independent C3PAO certification at Level 2 for contracts involving sensitive CUI, was scheduled for Nov. 10, 2026, before the Department of War suspended it on July 13, 2026. Phases 3 and 4, covering government-led Level 3 DIBCAC assessments, remain frozen as well.
Contractors already under contract with a C3PAO or DIBCAC requirement should confirm with their contracting officer whether that requirement is being amended out under the department's July 2026 guidance, and should not assume a solicitation's original terms still apply without written confirmation.
What Defense Contractors Should Do Now
- Validate SPRS scores and assessment accuracy before the next required affirmation
- Conduct an independent cybersecurity gap assessment rather than relying solely on internal self-scoring
- Review system security plans and plans of action and milestones (POA&Ms) for completeness
- Verify cloud providers and third parties meet contractual FedRAMP and DFARS obligations
- Document remediation activities and accepted risks with dates and evidence
- Confirm with contracting officers whether existing C3PAO or DIBCAC requirements are being amended under the Phase 2 pause
- Submit feedback to the CMMC Reform Task Force before the request for information closes
- Ensure executive leadership understands cybersecurity contractual obligations don't pause along with the certification schedule
Beyond Compliance to Real Security
While enforcement actions focus heavily on compliance failures, the underlying issue remains national security risk. Defense contractors manage information actively targeted by foreign intelligence services, cybercriminal organizations, nation-state threat actors, and supply chain attackers.
Weak cybersecurity within the defense industrial base creates exploitable pathways into sensitive defense programs, technologies, operational plans, and research environments. Contractors should treat compliance as the starting point rather than the final objective. Effective cybersecurity requires continuous improvement, operational discipline, governance oversight, and honest assessment of risk, regardless of which office is checking the score.
Cost of Waiting
The financial cost of cybersecurity noncompliance extends far beyond settlement amounts. Companies facing enforcement actions often experience legal expenses, forensic investigation costs, operational disruption, reputational damage, customer distrust, contract loss, increased cyber insurance scrutiny, and acquisition and valuation complications.
For defense contractors, the inability to demonstrate credible cybersecurity governance may eventually become a direct barrier to competing for future federal work, independent of whether that governance is verified by a C3PAO or checked later by DOJ.
Taking Action Before Enforcement
Defense contractors can't afford to wait for subpoenas, whistleblower complaints, failed assessments, or security incidents before addressing cybersecurity deficiencies. The Phase 2 pause gives contractors more time before a third-party audit is required, not more time before their self-reported score matters.
Companies should begin with honest assessments of their current security posture, accurate documentation of deficiencies, and realistic remediation planning aligned to contractual requirements.
Contractors that proactively identify and address deficiencies place themselves in a significantly stronger position than companies attempting to minimize or conceal security weaknesses. Cybersecurity within the defense industrial base isn't simply a technical challenge. It's a core component of contractual performance, enterprise governance, and national security responsibility.
Frequently Asked Questions
Did the CMMC Phase 2 suspension cancel CMMC?
No. The Department of War suspended the transition to independent third-party certification that was scheduled for Nov. 10, 2026. CMMC Phase 1 self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 implementation, and SPRS reporting all remain in effect.
Does the Phase 2 pause reduce False Claims Act risk?
No. Self-assessment scores submitted to SPRS still carry False Claims Act exposure if they're inaccurate. The LOGZONE settlement in June 2026 was built on a self-reported score, not a third-party audit.
What was the LOGZONE settlement about?
LOGZONE Inc., a defense contractor, agreed to pay $507,144 in June 2026 to resolve allegations it knowingly failed to meet cybersecurity requirements in its contracts with the Department of the Navy.
What is the Civil Cyber-Fraud Initiative?
It's a DOJ enforcement program launched in 2021 that targets government contractors and grant recipients who knowingly misrepresent their cybersecurity practices, conceal known deficiencies, or continue billing the government while materially noncompliant.
What should contractors do while CMMC Phase 2 is under review?
Contractors should keep meeting Phase 1 self-assessment and affirmation obligations, confirm with contracting officers whether existing third-party assessment requirements are being amended out, and consider submitting feedback to the CMMC Reform Task Force's public request for information.
Are You Prepared for CMMC and False Claims Act Scrutiny?
STACK Cybersecurity helps defense contractors assess cybersecurity maturity, identify compliance gaps, and prepare for Cybersecurity Maturity Model Certification and evolving federal cybersecurity requirements.
Talk to a CMMC Specialist